External reviews
External reviews are not included in the AWS star rating for the product.
Simplified and Streamlined
What do you like best about the product?
We loved the policy generators to help us make sure we are covering all of our bases. And then the gap analysis reports for internal tracking and the option to share reports to prospective and existing clients have been truly valuable.
What do you dislike about the product?
We use a few tools and services that don't integrate with Vanta (at least not yet). We would also love to see better integrated (or even Vanta created) annual required security training for our employees.
What problems is the product solving and how is that benefiting you?
We originally signed up with Vanta so that we could help ensure we were following best practices and answering all of the vendor questionnaires that our customers and potential customers send us. We hope to complete our first SOC 2 audit and certification process in the near future as well. Vanta has definitely helped with trust from customers and fulfilling many of their requirements.
- Leave a Comment |
- Mark review as helpful
Currently in pre-audit for our first soc2 audit and Vanta has made the process super easy.
What do you like best about the product?
Vanta keeps all my tasks in a short list, and makes it super easy to find what I need to work on next.
Also provides preformatted templates you can use as a small business who likely doesn't have all the docs in a row before an audit.
Also provides preformatted templates you can use as a small business who likely doesn't have all the docs in a row before an audit.
What do you dislike about the product?
The UI is kind of confusing at first, though when you use the product you get used to where things are.
What problems is the product solving and how is that benefiting you?
We're working toward automating our audit processes, and currently it's just one person running the entire audit for the company... in previous companies it took a team of people.
An organized and well-integrated platform that helped us manage our cloud security and policies.
What do you like best about the product?
The task-based approach to managing cloud security and policies. The dynamically-generated security reports. The integration with many of our
What do you dislike about the product?
Nothing. In the ~6 months we've been using Vanta, our experience has been nothing but positive.
What problems is the product solving and how is that benefiting you?
Managing our cloud infrastructure. Generating security policies. Preparing for SOC-2 Type II audit. Generating dynamic security reports for prospective customers.
Makes security compliance easy and (almost) fun
What do you like best about the product?
Simple, clean interface for managing the complexities of SOC II compliance. The policy management features are particularly useful. Vanta isn't just a tool for managing docs — it helped us to clarify our processes and organize our thinking around security compliance issues. It's hard/impossible to get a sense of best practices when you're pursuing SOC 2 on your own.
What do you dislike about the product?
Could always benefit from more integrations with vendors. We had to do a little extra work to chase lesser known cloud vendors.
What problems is the product solving and how is that benefiting you?
Vanta practically gamifies SOC compliance. We actually enjoyed the process, at least as much as such a thing is possible.
The primary benefit for us was achieving SOC 2 Type 2 compliance. This has opened up the door for sales growth, particularly in enterprise accounts where security compliance can be a major hurdle for smaller service providers like us.
The primary benefit for us was achieving SOC 2 Type 2 compliance. This has opened up the door for sales growth, particularly in enterprise accounts where security compliance can be a major hurdle for smaller service providers like us.
Very pleased with this compliance tool
What do you like best about the product?
I like the UI; it's a very clean platform that makes tracking our team's various security controls much easier.
What do you dislike about the product?
It would be great for more policy templates to be provided and for alerts to be sent out.
What problems is the product solving and how is that benefiting you?
I want to be able to easily use Vanta for any security audit, not just SOC2. However I have realized that with some effort it can work well for any audit.
SOC-2 helper for startups
What do you like best about the product?
Ease of use and automated checks of our infrastructure
What do you dislike about the product?
More integrations would be awesome. JAMF integration is welcome.
What problems is the product solving and how is that benefiting you?
SOC-2 compliance
Head of Growth
What do you like best about the product?
So easy to use! Out of the box setup was plug and play. It integrated with all of our stack and the vendors that they recommended for us have been really easy to work with.
Their customer support is fast and responsive. When issues arise they fix them quickly.
Their customer support is fast and responsive. When issues arise they fix them quickly.
What do you dislike about the product?
There are some bugs that pop up from time to time. The policy wizard isn't 100% intuitive.
It's a bit funky to disable the monitoring and I wish they could incorporate some outside systems, but early stage.
It's a bit funky to disable the monitoring and I wish they could incorporate some outside systems, but early stage.
What problems is the product solving and how is that benefiting you?
SOC2 Type II
Security and time-savings - double win
What do you like best about the product?
Clear ROI for us. Relatively easy to configure to our existing tech stack. Easy to implement policies. Best of all, a majority of documentation was available to our auditors from inside the tool.
What do you dislike about the product?
Setup wasn't insignificant. But if the goal is SOC2 compliance, as it was for us, the time spent is worth it.
What problems is the product solving and how is that benefiting you?
We needed to spend less time on security compliance and have more proof to show our customers. Vanta provided that with security reports immediately after configuration. Then it set the stage for a pretty painless audit.
Recommendations to others considering the product:
Security is critical, so make time to get it setup correctly with your tech stack. We also used their recommended audit partners, who were well versed with how the software works. Getting the SOC2 program going isn't trivial, but Vanta provides a terrific hub for it.
Great product makes SOC2 certification easy
What do you like best about the product?
Turnkey audit evidence that covers 90% of SOC2 auditor questions.
Made Type I audit a breeze.
Made Type I audit a breeze.
What do you dislike about the product?
Out of the box policies were a little too corporate for our use. They were a good basis to build and soften our policies.
Early adopter meant that not every integration we used was covered at the time.
Would like greater detail or insight into control coverage, more robust risk and vendor management.
Early adopter meant that not every integration we used was covered at the time.
Would like greater detail or insight into control coverage, more robust risk and vendor management.
What problems is the product solving and how is that benefiting you?
Security control justification.
Suggestion of vendors to meet control requirements (looking at integrations Vanta offers)
Audit readiness & evidence capture.
Suggestion of vendors to meet control requirements (looking at integrations Vanta offers)
Audit readiness & evidence capture.
Recommendations to others considering the product:
If the integrations cover your needs, it makes SOC2 certification so much easier.
Message to early stage companies: Save time and money automating your SOC with Vanta
What do you like best about the product?
Deep integrations with virtually every major tech stack. Connecting AWS, Google, GitHub, & Jira took automated what used to take us weeks of evidence gathering prior to using Vanta.
What do you dislike about the product?
Integrations are awesome, but it would be great if they built a framework for us to build some of our own checks! There's some weird stuff we do that other companies probably don't (everyone's got their own sauce), and I'd be happy to write my own integration to send up various pieces of evidence from our own stack.
What problems is the product solving and how is that benefiting you?
They make evidence gathering so easy that you can focus your time and energy getting your system securely setup rather than spending your time and energy taking screenshots of weird admin panels and system configurations that you then have to tediously explain to an auditor what it means and why it's reasonable evidence.
Recommendations to others considering the product:
If you're an early stage company skeptical about spending extra money on compliance, consider that the cost of contracting with Vanta will lower the cost of your audit. It saves both you and your auditor time, so you'll end up paying less or the same amount overall. Plus, Vanta offers great references for ancillary services you'll inevitably need such as a penetration test, etc. They can help you find a cost effective auditor and connect you with resources that best-fit your organization and budgetary needs.
showing 1,381 - 1,390